Cybersecurity

CVE Vulnerability Alerts
Critical FortiMail Zero-Day Exploited With No Patch Yet
Fortinet confirmed active exploitation of a critical FortiMail flaw with no fix shipped for most versions, and CISA added it to its exploited list.
Cybersecurity
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
A ten-country police operation seized KillSec's servers and leak site, arrested a suspected 16-year-old ringleader, and recovered over 110TB of stolen data.
Application Security
Kiteworks Patches Second Max-Severity Flaw in a Week
Kiteworks patched a maximum-severity code injection flaw found through its bug bounty program, marking its second critical disclosure in roughly a week.
Application Security
Self-Healing WordPress Backdoor Defies Standard Removal
Sucuri found a WordPress backdoor, SC, that persists across eight file, database, and memory locations and rebuilds itself when any one is deleted.
CVE Vulnerability Alerts
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
Cisco patched a critical authentication bypass in Catalyst SD-WAN Manager, formerly vManage, that attackers are actively exploiting to seize full admin control.
Cybersecurity
MetaMask Discloses Incident, Exits Ethereum Validators
MetaMask disclosed a security incident affecting its staking infrastructure and is proactively exiting Ethereum validators it runs through the Lido protocol.
CVE Vulnerability Alerts
TeamViewer Patches Critical Access-Control Bypass Flaw
TeamViewer patched a critical access-control bypass and four other flaws in its Full Client and Host software, urging all users to update immediately.
CVE Vulnerability Alerts
WatchGuard Patches Critical Root Code Execution Flaw
WatchGuard patched a critical Fireware OS flaw letting a rogue VPN server run root commands on Firebox appliances, plus 14 other bugs in the same ...
CVE Vulnerability Alerts
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
CISA warned that a pre-authentication flaw in MikroTik RouterOS lets a single crafted request trigger root code execution or crash the device remotely.
Cybersecurity
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
The FTC confirmed it is investigating OpenAI, Anthropic, and other AI firms after agents reportedly went beyond instructions to hack external websites.